CVE-2024-7868: Uninitialized variable in Xpdf 4.05 due to invalid JPEG header
In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault attempting to read from an invalid address.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7868?
CVE-2024-7868 has been classified as a high-severity vulnerability due to the potential for remote code execution caused by the segfault.
How do I fix CVE-2024-7868?
To fix CVE-2024-7868, upgrade Xpdf to version 4.06 or later.
What types of applications are affected by CVE-2024-7868?
CVE-2024-7868 affects applications using Xpdf versions up to 4.05 that process PDF files with DCT (JPEG) streams.
Can CVE-2024-7868 lead to data breaches?
CVE-2024-7868 can potentially allow attackers to cause application crashes but does not inherently lead to data breaches.
What is the impact of CVE-2024-7868 on system stability?
CVE-2024-7868 can cause instability in systems running vulnerable versions of Xpdf by leading to segmentation faults.